legal
Privacy Policy
Last updated: 31 August 2026
This Privacy Policy explains how Focused Productivity Pte. Ltd. (UEN 202311385N), trading as Sync 365 (we, us or our), collects, uses, discloses and protects personal data in connection with the Sync 365 website, accounts, sales, support and software-as-a-service platform.
Our registered office is 77 High Street, #10-12B, High Street Plaza, Singapore 179433. Our privacy and data-protection contact is info@sync365license.com.
1. Scope and our data protection roles
This Policy applies when we decide why and how personal data is used, for example when you visit our website, request a demo, create or administer a business account, buy a subscription, contact support, receive business communications or use our revenue leak calculator. In those situations, we act as an organisation under Singapore’s Personal Data Protection Act 2012 (PDPA) and, where applicable, a controller under the EU GDPR or UK GDPR.
Our business customers may configure Sync 365 to process information from Microsoft, Entra ID, Exchange, Azure, ConnectWise Manage, Autotask PSA, HaloPSA or another customer-selected service. For personal data in that Customer Data, the customer normally decides the purpose and means of processing and we act as its processor, subprocessor or data intermediary. That processing is governed by our Data Processing Addendum (DPA) and the customer’s instructions, not by this Policy alone.
If you are an employee, user, contact or end customer of a Sync 365 customer and your question concerns Customer Data, contact that customer first. We will assist the customer as required by the DPA and applicable law.
2. Personal data we collect
The information we collect depends on how you interact with us and which Services a customer configures.
2.1 Business, account and communication data
We may collect:
- name, employer, job title and business contact details;
- account identifiers, administrator role, subscription and plan information;
- authentication, sign-in, security and audit information;
- sales enquiries, demo and booking details, support messages and feedback;
- marketing preferences and records of notices or consents; and
- transaction, invoice, tax and payment-status information. Payment card details are handled by the payment provider shown at checkout and are not stored by this website.
We receive this data from you, your employer or organisation, an account administrator, our account and payment systems, or when you communicate with us.
2.2 Website, device and consent data
When you use the website, we and our website providers may receive IP address, browser and device type, operating system, requested pages, referral source, approximate location derived from IP, timestamps, diagnostic data and security events.
Our consent manager stores your privacy choices in browser local storage. Optional analytics and marketing technologies remain off unless you allow them. The Cookie Policy describes the current technologies and how to change your choice.
2.3 Forms, calculators and reports
If you submit a form or request a calculator report, we may collect your name, business email, company, selected PSA, high-level tenant, licence, Azure, managed-user, recurring-service and billing-process inputs, the generated estimates or report, submission time and follow-up consent. Please do not include customer names, credentials, tenant secrets, invoice exports or other unnecessary personal data in a free-text field.
2.4 Customer Data processed for customers
Depending on customer configuration, Customer Data may include:
- Microsoft partner, customer and tenant identifiers;
- business users and contacts, including name, business email, telephone, job title, office, department, city, state, country, company, domain and enabled status;
- Entra ID user, group, assigned-licence and extension-attribute information;
- Exchange mailbox metadata where the customer enables a supported feature;
- Microsoft licences, subscriptions, commitment terms, quantities and Azure subscription or consumption information;
- PSA company, site, contact, product, agreement, contract, billing and mapping records;
- End User Portal users, catalogues, orders, subscription details, customer pricing and branding; and
- configuration, integration, security, diagnostic and audit records.
The exact fields are determined by the customer, its permissions, the features it enables and the connected service. Sync 365 is not designed to require special-category data, criminal-offence data, government identity numbers, health records or consumer payment-card data in Customer Data. Customers should not configure free-text or custom fields to send that information unless we have expressly agreed appropriate safeguards in writing.
2.5 Data from connected and third-party services
We receive data from Microsoft and customer-selected PSA or related services when an authorised customer connects them. We may also receive business contact, booking, support and payment-status data from the providers used for those functions. Those third parties may separately process data under their own notices and their contracts with you or the customer.
3. Why we use personal data and our lawful bases
Where the EU GDPR or UK GDPR applies, we rely on the lawful basis identified below. Singapore and other laws may use different legal concepts, including consent, deemed consent, contractual necessity, legitimate interests and legal obligations.
Provide and administer the Services
We use account, business-contact, subscription, support, security and Customer Data to create accounts, provide configured features, authenticate users, connect integrations, process customer instructions, deliver support and communicate about the Services.
Our lawful bases are performance of a contract with an individual, steps requested before a contract, and our legitimate interests in providing and administering B2B services. For Customer Data, we act on the customer’s documented instructions under the DPA.
Operate integrations and customer-directed syncs
We retrieve, compare, map, calculate and transmit supported data between customer-authorised Microsoft, Sync 365 and PSA workflows. This can include contact sync from Microsoft 365 or Entra ID into a customer-controlled Autotask account.
For Customer Data, the customer determines the lawful basis and instructs us through its configuration and use of the Services.
Secure, monitor and troubleshoot
We use account, device, access, diagnostic and event information to prevent abuse, protect accounts and infrastructure, investigate incidents, maintain availability and enforce our agreements.
Our lawful bases are legitimate interests in securing the Services and complying with legal obligations.
Process subscriptions, payments and records
We use business-contact, order, invoice, tax and payment-status data to administer subscriptions, collect fees, keep financial records and manage disputes.
Our lawful bases are contract, legitimate interests in managing our business, and legal obligations.
Respond to enquiries and support requests
We use the information you provide to answer questions, arrange demonstrations, generate requested reports, investigate issues and follow up where you ask us to.
Our lawful bases are requested pre-contract steps, contract, consent where required, and legitimate interests in responding to business enquiries and supporting customers.
Improve and understand our services
We use feedback, service telemetry, aggregated statistics and de-identified information to understand reliability and feature use and improve our products. We use Customer Personal Data for this purpose only where the customer’s instructions and applicable law permit it.
Our lawful basis for controller data is legitimate interests in improving the Services. Optional website analytics depend on your consent where required.
Send business marketing
We may send relevant product and event information to business contacts where permitted by law. You can unsubscribe at any time. Optional advertising, audience measurement and business-interest identification tools on the website operate only after the relevant consent choice.
Our lawful bases are consent where required and legitimate interests in marketing B2B services, balanced against your rights.
Meet legal obligations and protect rights
We may use and disclose information to comply with law and valid legal process, establish or defend legal claims, protect people or property, and support a corporate transaction subject to appropriate confidentiality.
Our lawful bases are legal obligation and legitimate interests in protecting our business and others.
4. How we disclose personal data
We disclose only the information reasonably needed for the relevant purpose. Recipient categories include:
- Cloud infrastructure: Microsoft Azure hosts the Sync 365 application in the North Europe region in Ireland and provides related managed infrastructure, database, backup, logging and security services.
- Website delivery and security: Cloudflare provides website hosting, delivery, request security and limited website-worker functions, including processing calculator submissions before onward delivery.
- Sales, support and forms: Zoho services support website forms, customer relationship management, support and, with consent, PageSense analytics. Demo-booking and embedded-content providers process information when you choose to use those features.
- Analytics and marketing: with the relevant website consent, providers may include Google Analytics and Ads, Zoho PageSense, RB2B, LinkedIn, Meta and Reddit. Current details are in the Cookie Policy.
- Account and payment services: our account portal and the payment processor presented at checkout process order, account, payment and fraud-prevention information under their own terms.
- Approved subprocessors: providers used to process Customer Personal Data on our behalf are identified in the DPA. We contractually restrict their processing and remain responsible as required by applicable law.
- Customer-selected integrations: Microsoft, ConnectWise Manage, Autotask PSA, HaloPSA and another integration selected and controlled by the customer receive data at the customer’s instruction. They are not our subprocessors merely because Sync 365 connects to them.
- Professional advisers and authorities: auditors, insurers, legal and professional advisers, courts, regulators, law enforcement and other authorities where reasonably necessary and lawful.
- Corporate transactions: a prospective buyer, investor or successor under confidentiality and appropriate data-protection safeguards.
We do not sell personal data for money. Some optional advertising or business-identification activity may be treated as a “sale”, “sharing” or targeted advertising under certain US state laws even where no money changes hands. You can reject or withdraw those optional technologies through Privacy settings in the website footer and may contact us to exercise an applicable state-law right.
5. International transfers
The Sync 365 application’s primary Customer Data hosting region is Microsoft Azure North Europe in Ireland. Focused Productivity is a Singapore company, and authorised support, security and operational access may occur from Singapore. Some website, communications and support providers may process personal data in other countries identified in their terms or our DPA.
Where personal data is transferred internationally, we use a legally recognised safeguard as required, which may include:
- the European Commission’s 2021 Standard Contractual Clauses, using the controller-to-processor or processor-to-processor module as appropriate;
- the UK International Data Transfer Addendum to those clauses or the UK International Data Transfer Agreement;
- a transfer assessment and supplementary technical or organisational measures where required;
- a legally binding contract requiring protection comparable to Singapore’s PDPA; or
- an adequacy decision or another lawful transfer mechanism.
The DPA contains the transfer framework for Customer Personal Data. A copy of the relevant contractual safeguard can be requested from our privacy contact, subject to redaction of confidential information.
6. Retention and deletion
We keep personal data only while reasonably needed for the purposes described above, to follow customer instructions, and to meet legal, accounting, security and dispute-resolution obligations. In deciding a period, we consider the amount, nature and sensitivity of the information, risk of harm, purpose and legal requirements.
In particular:
- Customer Data is available for an export request during the subscription and normally for 60 days after termination, after which active copies are deleted or made inaccessible unless law requires retention;
- protected backup copies remain isolated from ordinary use and are overwritten or deleted through the applicable backup lifecycle;
- account, contract, invoice, tax and payment records are retained for the relationship and the period required to meet legal and accounting obligations;
- sales, support, booking and report-request records are retained while needed to respond, manage the relationship, honour preferences and resolve disputes; and
- website consent choices and optional technologies follow the periods described in the Cookie Policy and provider settings.
Customers can request deletion or return of Customer Personal Data as set out in the DPA.
7. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and access. Measures include access restrictions, authentication controls, encryption in transit and at rest where appropriate, protected secrets, logging, backups, controlled production changes, incident handling and data minimisation. No internet or storage system is completely secure.
The DPA describes the measures applicable to Customer Personal Data. Customers remain responsible for their users, endpoint security, connected-service permissions, secure credentials, least-privilege configuration and review of Sync 365 outputs.
If you believe personal data or an account has been compromised, contact us promptly at info@sync365license.com.
8. Your rights and choices
Your rights depend on the law that applies and may be subject to exceptions. They can include the right to:
- receive information about processing and obtain access to personal data;
- correct inaccurate or incomplete personal data;
- request deletion or restriction;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent without affecting earlier lawful processing;
- receive certain data in a portable format;
- opt out of sale, sharing or targeted advertising where applicable; and
- complain to a data-protection authority.
To exercise a right relating to data we control, email info@sync365license.com. We may need to verify your identity and authority. We will respond within the period required by applicable law.
For Customer Data, contact the relevant Sync 365 customer first. If we receive your request directly, we may refer it to that customer and assist it under the DPA.
You can change optional website tracking at any time through Privacy settings in the footer. You can unsubscribe from a marketing email using its unsubscribe link.
You may complain to the Singapore Personal Data Protection Commission. If the EU GDPR or UK GDPR applies, you may also complain to the supervisory authority where you live or work, including the UK Information Commissioner’s Office for the United Kingdom.
9. Automated decisions
We do not use personal data that we control to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Sync 365 automates customer-configured business workflows, but the customer controls its configuration and remains responsible for reviewing consequential billing, ordering, provisioning and contact decisions.
10. Children
The Services are for businesses and Authorised Users aged 18 or over. They are not directed to children, and we do not knowingly collect children’s personal data for our own purposes. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action.
11. External sites and customer services
Our website and Services may link to or connect with third-party sites and customer-controlled services. Their privacy practices are governed by their own notices and agreements. Customer administrators should review the permissions and privacy terms of every service they connect to Sync 365.
12. Changes to this Policy
We may update this Policy when our Services, providers or legal obligations change. We will post the new version and update the date above. If a change materially affects how we use personal data, we will provide additional notice where required.
13. Contact us
Focused Productivity Pte. Ltd. is responsible for this Policy and has designated a data-protection contact for enquiries and complaints.
Focused Productivity Pte. Ltd. (UEN 202311385N)
Trading as Sync 365
77 High Street, #10-12B
High Street Plaza
Singapore 179433
Email: info@sync365license.com
For Customer Data processing terms, see the Data Processing Addendum.
